View Hospital | 2026 Update with complete solutions
DKN1 TASK 1: Penetration Test Report Analysis
Anonymous
College of Information Technology, Western Governors University
Western View Hospital Penetration Test
A1. Client Goals
Western View Hospital, a 100-bed rural medical facility, has engaged Pruhart Tech to
conduct a penetration test to evaluate the overall security controls of its information
technology environment. The primary objective is to determine if the practical controls
currently in place meet the Health Insurance Portability and Accountability Act of 1996
(HIPAA) guidelines for protecting patient health and financial data .
The hospital's IT environment comprises an on-premise Active Directory (AD) environment
that manages access and identification for medical staff . The network is a hybrid of wired
and wireless systems accessed via personal computers, laptops, and mobile devices. The
organization generates and houses both Protected Health Information (PHI) and electronic
Protected Health Information (e-PHI) in physical and electronic locations, including host
machines and server infrastructure. The ultimate goal is to ensure that its electronic health
records and financial data are protected from breaches to avoid significant fines, legal
consequences, and loss of reputation .
A2. Penetration Testing Engagement Plan Structure
The current Penetration Test Engagement Plan from Pruhart Tech is structured in two broad
phases :
1. Internal Network & System Testing: Pruhart Tech will be provided a secure sensor
within the internal environment to conduct vulnerability scanning. From this position,
, the team will attempt to compromise the AD environment and endpoints by launching
the EternalBlue attack. The goal is to identify which systems can be compromised and
what PHI data can be accessed.
2. Social Engineering: The second phase involves social engineering via phone calls,
where the team will pose as IT contracted staff. They will attempt to convince
Western View team members to log onto their IT-provided device and, when the effort
fails, ask for their credentials. Successful attempts will be used to gain access and
attempt to compromise PHI data.
A3. Misalignments
After reviewing the client's goals and the engagement plan, several critical misalignments
have been identified that prevent the plan from achieving its primary objective:
comprehensive HIPAA compliance review.
The HIPAA Security Rule requires covered entities to maintain reasonable and appropriate
administrative, technical, and physical safeguards for protecting e-PHI . While the current
plan has considerations for testing some technical controls, it leaves significant gaps in
compliance testing:
1. Physical Controls: The engagement plan limits physical control testing to phone-
based social engineering attempts. Since Western View Hospital is a public building,
other physical tests should be conducted to gauge how well e-PHI is being protected.
Tests are needed to see if unauthorized personnel can gain physical access to
electronic information systems located around the hospital, including server rooms
and network closets .
2. Technical Controls (Data in Transit): The plan does not address testing for data
encryption in transit. HIPAA requires a mechanism to encrypt e-PHI . While the
current tests could discover if data at rest is encrypted, the plan does not discuss
evaluating whether data is encrypted as it moves across the network .
3. Reporting Phase: The current engagement plan does not include a formal customer
acceptance or reporting phase. To help Western View Hospital meet its goal of
, modernizing and securing patient records, it is imperative to provide post-
engagement activities to help the client understand and remediate vulnerabilities or
other deficiencies found during the testing activity .
B1. Best Practices and Frameworks
To create a comprehensive penetration testing plan aligned with HIPAA goals, several
industry-standard frameworks and best practices should guide the engagement.
1. The Penetration Testing Execution Standard (PTES)
PTES is a valuable resource that outlines the stages of a penetration test, ensuring best
practices and reliability. It is structured in seven key phases: Pre-engagement Interactions,
Intelligence Gathering, Threat Modeling, Vulnerability Analysis, Exploitation, Post Exploitation,
and Reporting .
Pre-engagement Interactions: This phase is crucial to ensure the client receives a
solid return on investment and the testing organization does not exceed the bounds
of the test, which could cause legal and production issues . It is also where the extent
of social engineering boundaries should be determined.
Reporting: The reporting phase is critical, as it produces two basic parts:
an Executive Summary and a Technical Summary . The Executive Summary is
aimed at key stakeholders and should provide an overview of the goals, high-level
findings, and a risk rating to help them understand the business impact. It should also
include a Recommendations section with a strategic roadmap. The Technical
Summary provides detailed technical evidence for validation and remediation teams.
2. The Open Source Security Testing Methodology Manual (OSSTMM)
This framework provides comprehensive guidance on how to conduct security assessments,
including specific focuses on physical security testing and data networks security testing .
Physical Security Testing: The OSSTMM emphasizes physical and logical barrier
testing and gap measurement to the required security standard. It includes verifying
physical security controls like cameras, alarms, locks, and access control logs.
, Data Networks Security Testing: For network testing, the OSSTMM recommends
reviewing the strength and design of encryption mechanisms. This is a key
requirement for HIPAA compliance reviews, as it requires encryption for both data at
rest and in transit.
3. The National Institute of Standards and Technology (NIST)
NIST offers several best practices that are directly relevant to this engagement.
NIST SP 800-115: This special publication identifies network sniffing as a best
practice for capturing and replaying network traffic, passive network discovery, and
identifying unencrypted transmission of sensitive information, such as usernames
and passwords . This is an ideal way to determine compliance with HIPAA's data-in-
transit confidentiality requirements.
NIST HIPAA Security Rule Crosswalk: This document helps align HIPAA compliance
with NIST recommendations. It recommends, as a best practice, that physical
access to assets must be managed and protected and that this could include
checking for physical barriers or testing if current physical protection standards
meet their intended purpose .
B2. Comparison of Plan to Best Practices and Frameworks
A comparison of the proposed plan against the frameworks above reveals significant
shortcomings:
Physical Security Testing: The current plan does not include a physical penetration
testing phase, failing to align with the recommendations from PTES, OSSTMM, and
NIST to ensure HIPAA compliance .
Data in Transit Testing: The plan lacks any testing for data in transit. This means it
will not verify if e-PHI is encrypted during transmission, which is a clear violation of
best practices outlined by OSSTMM and NIST for maintaining HIPAA compliance.
Reporting Framework: The plan does not incorporate a structured reporting phase
as recommended by PTES, which is essential for translating technical findings into
actionable business decisions and strategic improvements.